OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation (CVE-2026-34503) | HOL Guard CVE